using-git-worktrees

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill attempts to read configuration preferences from a local file (CLAUDE.md) using grep and instructs the agent to use the found value without further verification.
  • Ingestion points: The CLAUDE.md file (Step 2) is read to determine the worktree directory path.
  • Boundary markers: None. The agent is instructed to use the preference "without asking."
  • Capability inventory: The skill possesses the ability to execute shell commands (git, mkdir, echo), write to files (.gitignore), and install software packages.
  • Sanitization: No sanitization or validation of the input retrieved from CLAUDE.md is specified before it is used in subsequent shell commands.
  • [COMMAND_EXECUTION]: The skill automatically executes build and installation scripts based on the presence of project files.
  • Evidence: The "Post-Creation Setup" section automatically triggers npm install, cargo build, pip install, poetry install, and npm test based on the existence of package.json, Cargo.toml, or requirements.txt.
  • Risk: This executes code (install scripts or test suites) defined within the repository being worked on.
  • [EXTERNAL_DOWNLOADS]: The skill triggers the retrieval of external dependencies from public registries.
  • Evidence: Commands like npm install, go mod download, and poetry install fetch packages from external sources (npm, PyPI, Go Proxy, etc.) during the worktree setup process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:09 AM
Security Audit — agent-trust-hub — using-git-worktrees